Indonesia said it would not pay the US$8 million ransom demanded after ransomware disrupted its Temporary National Data Center 2 (PDNS 2) in Surabaya in June 2024. The incident affected government services, including immigration operations. Officials identified the malware as Brain Cipher, which they described as a newer development of LockBit 3.0, and pursued recovery through isolation, replacement servers and staged security checks.
What happened to Indonesia’s data center?
The disruption began on June 20, 2024, at PDNS 2, a temporary national data center in Surabaya. The incident was not reported as an attack on Indonesia’s permanent National Data Center (PDN): Communications and Informatics Minister Budi Arie Setiadi clarified, “The attack is not targeted at PDN but PDNS 2 in Surabaya.” Officials said they were conducting a forensic evaluation. Source: Indonesian officials, as reported by [c2]
Indonesia’s National Cyber and Crypto Agency (BSSN) identified Brain Cipher ransomware as the cause. BSSN chief Hinsa Siburian described it as a newer development of LockBit 3.0, saying forensic work had identified a “latest sample.” That describes the malware’s lineage; it does not establish who carried out the attack or their motive. Source: [c2]
Did Indonesia pay the ransom?
No. The attackers demanded US$8 million, and Setiadi said on June 24, 2024: “No, we will not (pay).” The demand and refusal were also reported by Reuters. Indonesian officials: [c2]; Reuters: [c5]
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Scan for outdated or missing drivers - takes under a minuteDriver Scan →#1 Best Overall
Which services were affected?
The disruption interrupted immigration services and other public services. Immigration-related operations reported as restored or prioritized included visas, passports, visas on arrival, checkpoint services and document management. Source: [c2]
ANTARA, citing government figures, reported that 211 public services were affected on June 24, 2024, rising to 282 on June 25. In a July 2024 update, officials reported that 86 public services across 16 state institutions had been restored. These are dated service counts, not counts of affected institutions or a claim that every disrupted service had been restored. Source: ANTARA, [c3]
How did Indonesia approach recovery?
Officials described a recovery plan combining containment, replacement infrastructure and checks before affected data returned to service. The connected infrastructure included PDNS 1 in Serpong, PDNS 2 in Surabaya and a cold-site backup in Batam. The government said PDNS 2 was isolated from connected systems and replacement servers were used while security protocols were strengthened. Source: [c4]
Three stages for affected data
- Red zone: Quarantine affected data. Coordinating Minister Hadi Tjahjanto said data affected by the incident was held there. Source: [c3]
- Blue zone: Harden security and scan for vulnerabilities.
- Green zone: Release data after the checks are complete.
Authorities presented this staged process as a way to reduce the risk of restoring compromised or unsafe data directly to operating systems. Their reported updates describe services restored by July, but do not establish that the entire system or every affected service was fully recovered by then. Source: [c3]
Rank #3
What is known about the attackers?
The available official account identifies the ransomware as Brain Cipher and links its development to LockBit 3.0. It does not verify the identity of the people or group behind the incident, nor their motive. Malware lineage alone is not proof of who deployed it.
Quick Recap
Best Value
Rank #4
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

